CVE-2025-13027

8.1

Mozilla · Firefox and Thunderbird

Memory safety vulnerabilities in Mozilla Firefox and Thunderbird 144 may allow for memory corruption and potential arbitrary code execution.

Executive summary

Mozilla Firefox and Thunderbird version 144 contain critical memory safety defects that could permit an unauthenticated attacker to achieve arbitrary code execution via memory corruption.

Vulnerability

The software contains multiple memory safety bugs that result in memory corruption. These flaws are reachable by an unauthenticated attacker, who could leverage them to execute arbitrary code on the host system.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, including the loss of data confidentiality, integrity, and availability. With a CVSS score of 8.1, this vulnerability is classified as High, reflecting the significant danger posed by successful exploitation of memory safety flaws in widely used browser and email client applications.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 145 or later to apply the necessary security patches.

Proactive Monitoring: Monitor endpoint systems for unexpected application crashes, which may indicate attempted exploitation of memory corruption vulnerabilities.

Compensating Controls: Ensure that systems are running with standard exploit mitigations, such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR), which may complicate exploitation attempts.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists on GitHub.

Analyst recommendation

Given the nature of memory safety bugs and their potential to facilitate arbitrary code execution, this vulnerability represents a significant threat to internal systems. Administrators should prioritize the deployment of version 145 across all workstations to ensure these critical security gaps are closed immediately.

More Mozilla CVEs

Sources

Originally found and disclosed by The Mozilla Fuzzing Team, per the CVE Program record.